44 push :
55 branches : [main]
66
7+ concurrency :
8+ group : ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
9+ cancel-in-progress : true
10+
711permissions : {}
812
913jobs :
1014 release-please :
15+ name : Release Please
1116 runs-on : ubuntu-latest
1217 environment : release
1318 permissions :
14- contents : write
15- pull-requests : write
19+ contents : write # Create releases, tags, and release branches
20+ pull-requests : write # Open and update pin README pull requests
1621 steps :
1722 - uses : googleapis/release-please-action@16a9c90856f42705d54a6fda1823352bdc62cf38 # v4.4.0
1823 id : release
@@ -28,41 +33,48 @@ jobs:
2833 if : ${{ steps.release.outputs.release_created }}
2934 env :
3035 GITHUB_TOKEN : ${{ github.token }}
36+ GITHUB_REPOSITORY : ${{ github.repository }}
37+ RELEASE_MAJOR : ${{ steps.release.outputs.major }}
38+ RELEASE_TAG_NAME : ${{ steps.release.outputs.tag_name }}
3139 run : |
3240 git config user.name "github-actions[bot]"
3341 git config user.email "github-actions[bot]@users.noreply.github.com"
34- git remote set-url origin "https://x-access-token:${GITHUB_TOKEN}@github.com/${{ github.repository } }.git"
35- git tag -fa "v${{ steps.release.outputs.major } }" \
36- -m "Release v${{ steps.release.outputs.tag_name } }"
37- git push origin "v${{ steps.release.outputs.major } }" --force
42+ git remote set-url origin "https://x-access-token:${GITHUB_TOKEN}@github.com/${GITHUB_REPOSITORY }.git"
43+ git tag -fa "v${RELEASE_MAJOR }" \
44+ -m "Release v${RELEASE_TAG_NAME }"
45+ git push origin "v${RELEASE_MAJOR }" --force
3846
3947 - name : Pin README to release SHA
4048 if : ${{ steps.release.outputs.release_created }}
4149 env :
4250 GH_TOKEN : ${{ github.token }}
51+ RELEASE_SHA : ${{ steps.release.outputs.sha }}
52+ RELEASE_TAG_NAME : ${{ steps.release.outputs.tag_name }}
4353 run : |
4454 sed -i -E \
45- ' s|developmentseed/action-python-security-auditing@[^ ]+( # v[0-9][^ ]*)?|developmentseed/action-python-security-auditing@${{ steps.release.outputs.sha }} # ${{ steps.release.outputs.tag_name }}|g' \
55+ " s|developmentseed/action-python-security-auditing@[^ ]+( # v[0-9][^ ]*)?|developmentseed/action-python-security-auditing@${RELEASE_SHA} # ${RELEASE_TAG_NAME}|g" \
4656 README.md
4757 git add README.md
4858 git diff --cached --quiet && echo "README unchanged, skipping commit" && exit 0
49- BRANCH="chore/pin-readme-${{ steps.release.outputs.tag_name } }"
59+ BRANCH="chore/pin-readme-${RELEASE_TAG_NAME }"
5060 git checkout -b "$BRANCH"
51- git commit -m "chore: pin README to ${{ steps.release.outputs.tag_name } }"
61+ git commit -m "chore: pin README to ${RELEASE_TAG_NAME }"
5262 git push origin "$BRANCH"
5363 gh pr create \
54- --title "chore: pin README to ${{ steps.release.outputs.tag_name } }" \
55- --body "Automated: pin README SHA references to release ${{ steps.release.outputs.tag_name } }." \
64+ --title "chore: pin README to ${RELEASE_TAG_NAME }" \
65+ --body "Automated: pin README SHA references to release ${RELEASE_TAG_NAME }." \
5666 --base main \
5767 --head "$BRANCH"
5868
5969 - name : Notify tests repo to update action pin
6070 if : ${{ steps.release.outputs.release_created }}
6171 env :
6272 GH_TOKEN : ${{ secrets.TESTS_REPO_DISPATCH_TOKEN }}
73+ RELEASE_SHA : ${{ steps.release.outputs.sha }}
74+ RELEASE_TAG_NAME : ${{ steps.release.outputs.tag_name }}
6375 run : |
6476 gh api repos/lhoupert/action-python-security-auditing-tests/dispatches \
6577 --method POST \
6678 -f event_type=action-release \
67- -F client_payload[sha]='${{ steps.release.outputs.sha }}' \
68- -F client_payload[tag]='${{ steps.release.outputs.tag_name }}'
79+ -F " client_payload[sha]=${RELEASE_SHA}" \
80+ -F " client_payload[tag]=${RELEASE_TAG_NAME}"
0 commit comments